Skip to content

Cybersecurity Burnout Is a Risk Signal. Pizza Parties Won't Fix It.

Veteran CISO Kayla Williams tells CYBR.Minded that overloaded security teams create measurable cyber risk through slower escalation, weaker judgment and missed signals — and CISOs should start tracking the warning signs.

Cybersecurity teams can have talented people, modern tools and mature policies and still find themselves operating under conditions that steadily increase risk.

The problem, according to cybersecurity executive Kayla Williams, is that organizations too often treat burnout as a workforce or wellness issue rather than what it can become: an operational cybersecurity risk.

Williams, founder of Kayla Williams Consulting and former CISO at Devo, joined host Dustin Sachs on the latest episode of CYBR.Minded to discuss the relationship between human strain and security performance.

Full episode:

Cybersecurity Burnout Is a Security Risk, Not an HR Issue
Kayla Williams explains how cybersecurity burnout weakens judgment, escalation and trust—and why pizza parties won’t fix the problem.

The premise of the conversation was straightforward: Security decisions are made by people working under pressure. When those people become overloaded, exhausted or reluctant to speak up, the effectiveness of the security program can deteriorate along with them.

“The human side is really all of it,” Williams said, arguing that people are essential not only to security operations but to maintaining processes and validating the output of technology, particularly AI systems. When organizations overwork those people, she said, mistakes and incidents become more likely.

Burnout can look like a security failure

One of the biggest mistakes leaders make, Williams said, is interpreting changes in employee behavior as an attitude or performance problem without asking what is causing them.

Consider a Tier 2 SOC analyst who stops escalating ambiguous alerts.

A manager might see someone becoming disengaged. Williams sees another possibility: deteriorating triage judgment caused by exhaustion.

An analyst suffering from alert fatigue may begin going through the motions — processing tickets, closing alerts and moving on — because the cognitive capacity required to connect ambiguous signals is eroding.

“The problem isn't that they're not happy in their job,” Williams said. “It's that they're just exhausted.”

That distinction matters because burnout does not necessarily look like someone visibly falling apart.

One employee may withdraw from meetings. Another may become irritable. Others may continue producing work at roughly the same pace while the quality of that work quietly declines.

That makes understanding individual team members important. Williams said she does not believe leaders should have more than seven direct reports because beyond that point it becomes difficult to develop the relationships needed to recognize when someone's behavior changes.

Related:

Former CISOs Launch AI Governance Advisory Firm
Two veteran CISOs launch an AI advisory firm to help enterprises govern AI deployments, reduce risk, and meet compliance goals.
AI Is Transforming Security. Burnout Is Reshaping Teams
A new ISSA/Omdia study finds widespread AI adoption in cybersecurity, but security professionals say growing complexity, burnout, skills shortages, and business pressures are making the profession more challenging than ever.
Deidre Diamond: Burnout Is Cybersecurity’s Bigger Crisis
Deidre Diamond says burnout, not hiring, is cybersecurity’s biggest workforce challenge. Learn what leaders should do next.

Psychological safety affects cybersecurity

Burnout isn't the only human factor that can degrade security performance.

Trust matters, too.

Williams argued that organizations need cultures where employees can report mistakes, confusion and near misses without fearing punishment or embarrassment.

If employees believe acknowledging a mistake could get them fired, written up or ridiculed, they have an incentive to keep quiet. That can deprive security teams of the early warning signals they need to prevent a near miss from becoming an incident.

“Cultures produce leading indicators,” Williams said.

An employee who admits they nearly clicked a malicious link, for example, may expose a weakness that security teams can address before somebody else actually falls for the attack. A blame-oriented culture can suppress exactly that kind of information.

For security leaders, that turns psychological safety into something much more tangible than an HR concern.

If people hesitate to report problems, information moves more slowly. If information moves more slowly, defenders have less time to react.

Start measuring workforce strain as cyber risk

Williams' argument also raises an obvious question: If burnout is cybersecurity risk, how should organizations measure it?

Most security organizations already track metrics such as ticket volumes, mean time to respond, training completion and vulnerability closures. Williams said leaders should also pay attention to key risk indicators, or KRIs, capable of exposing deteriorating operating conditions.

Among the indicators she suggested:

  • Escalation latency: How long does it take between an event occurring and someone escalating it?
  • After-hours alert acknowledgment: Are critical alerts increasingly going unacknowledged or missing established SLAs?
  • Retrospective escalation gaps: After an incident, how many warning signs were visible but never escalated?
  • Employee attrition: Are people leaving a particular security function unusually quickly, including during or shortly after onboarding?

The individual metric matters less than the trend.

If escalation times steadily increase, for example, leaders should ask what is interfering with the flow of information. The cause could be a broken process, an unhealthy culture, workforce strain or some combination of the three.

Williams pointed specifically to SOC and vulnerability management teams as places where these measurements can be valuable because both functions routinely operate against relentless workloads and, sometimes, unrealistic expectations.

Telling a vulnerability management team that its objective is to reach zero vulnerabilities, she noted, effectively gives employees a finish line they can never reach.

Pizza parties won't fix broken operating conditions

Improving team camaraderie can help, particularly for distributed teams. But Williams cautioned against confusing morale-building activities with fixing the source of burnout.

When a team is clearly struggling, leaders need to identify the underlying causes.

One approach she recommends is a “Five Whys” session facilitated by a neutral person rather than the security team's leader. The exercise repeatedly asks why a problem occurred until the team begins uncovering the processes and conditions underneath it.

The findings then need to become assigned action items.

Social gatherings and team-building still have value, Williams said, but “when something like this is going on and there's this perceived or known unhappiness across the team, you need to get to the bottom of it and address it.”

Security performance starts with operating conditions

Williams closed with another deceptively simple recommendation: Keep processes current.

Security teams inevitably develop shortcuts and workarounds as environments change. When those improvements remain trapped inside individual employees' heads instead of becoming part of shared processes, organizations create inefficiency, resentment and dependence on tribal knowledge.

Treating procedures as living documents can remove friction and save employees time while building trust across the team.

That gets to the larger point of the CYBR.Minded conversation.

Organizations don't have to choose between taking care of people and demanding strong security performance because the two are connected.

Chronic overload affects judgment. Low trust slows reporting. Poor processes create unnecessary work. Unrealistic goals exhaust teams. And eventually those human conditions can manifest as missed alerts, delayed escalations and weakened controls.

Burnout, in other words, isn't simply something happening to the people operating the security program.

It can be telling leaders something important about the security program itself.

HOU.SEC.CON CTA

Latest